The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an error page, which allows local users to read another user's inbox.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2005-11-16T21:17:00Z
Updated: 2024-09-16T23:40:38.467Z
Reserved: 2005-11-16T00:00:00Z
Link: CVE-2002-2165

No data.

Status : Deferred
Published: 2002-12-31T05:00:00.000
Modified: 2025-04-03T01:03:51.193
Link: CVE-2002-2165

No data.